Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 10.8.3, the exact Directus version number was being shipped in compiled JS bundles which are accessible without authentication. With this information a malicious attacker can trivially look for known vulnerabilities in Directus core or any of its shipped dependencies in that specific running version. The problem has been resolved in versions 10.8.3 and newer.
Cite this page
CVE-2024-27296. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2024-27296
Use CWE-200, Monospace vendor hub and Directus product page to widen CVE-2024-27296 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-35408, CVE-2026-39942 and CVE-2026-35442 for nearby disclosures in the same product family.